22 ms·
In addition on Android 11 API * apps can't simply access the "external" storage (enforces scoped storage) * apps can't get a list of all installed apps (packa
by sitic 6y ago
In addition on Android 11 API
* apps can't simply access the "external" storage (enforces scoped storage)
* apps can't get a list of all installed apps (package visibility, they can specify app names and intent signatures in the Manifest they want to query)
These are welcome changes in my view, but unfortunately they also seem intend to fix SafetyNet and require hardware attestation that the bootloader is not unlocked [1]. When this is enforced for all devices some apps, like the eBay app, won't run on unlocked devices anymore. I've always trusted CyanogenMod/LineageOS more then than a device manufacturer, but after >10 years of using Android I think it's finally time for me to switch to an iPhone.
[1] https://groups.google.com/forum/#!topic/safetynet-api-clients/lpDXBNeV7Fg https://groups.google.com/forum/#!topic/safetynet-api-client...
- j88439h84 6y agoWhat does external mean? SD card? or anything outside the app's own directory?
- igorstellar 6y agoExternal storage used to be a shared storage for apps outside of it's sandbox. Files are retained after app is uninstalled. [1] [1] https://developer.android.com/training/data-storage https://developer.android.com/training/data-storage
- vorpalhex 6y agoThis was abused by several apps to allow locating and identifying users illicitly. One app, say, WeChat, would ask for broad permissions for location and unique identifiers and then leave unique tracking identifiers in a shared file location. Than another app, say, a mobile game, could pick up on those shared identifiers and link you back. Why this would be a useful benefit worth setting up in an SDK across multiple companies and apps, I'll leave to your own imagination.
- kevin_thibedeau 6y agoThis would be solved if they just ported over the revokable permissions that LineageOS implements. You get real security and the app is none the wiser.
- grishka 6y agoIt's not like the switch to scoped storage would mitigate much of it. You can still do all kinds of nasty things when you, for example, have access to the photo library part of the MediaStore content provider. Like adding your tracking ID to the metadata of a picture that other app would then look for. Or, you could just create a "photo" and write your arbitrary data in place of the file contents. Users won't ever notice there's a broken image at the end of their camera roll. Will this change make it look more suspicious when apps request access to photos instead of storage? Yes, sure. Will most users care about it and deny access to apps that aren't supposed to have it? Of course not.
- usrusr 6y agoWhy would you even break the photo? Steganography goes back hundreds of years before computers. The only challenge is too make the user keep some of the watermarked pictures (the OS can keep you from writing to files created by other apps. They are sacrificing far too much for a fight they cannot win.
- CameronNemo 6y agoI wonder how this will impact my externally stored music library, which is accessed by two open source apps (Vanilla Music and Alarm Klock) but not managed by those apps or tied to their lifetimes.
- hddherman 6y agoI switched recently to an iPhone after 6 years on Android, including messing around with Cyanogenmod/LineageOS. It's not that bad, especially considering that Android is reaching the same level of lockdown that Apple has enforced, so you might as well use something that is reasonably secure and has official software update support for 5+ years.
- Iolaum 6y agoAs long as Google allows installation of apps outside the play store this will not happen. Moreover Google devices are the most open modern mobile devices out there now (I am intentionally excluding Librem5 and Pinephone). That is because on a Pixel you are allowed to relock the bootloader and load an image that you self signed!! This has spawned a niche ecosystem of android forks on pixel devices (look for RattlesnakeOS, GrapheneOS, CalyxOS).
- Vespasian 6y agoThe security changes are nice and needed so well done. Enforcing SafetyNet is probably also a net positive change, and you (and I) are a minority among the general user base. Sadly this was always coming, it was nice while it lasted, I guess. I'm not quite sure what I will do once my current phone dies. I don't see myself investing in the Apple ecosphere, so either go with the time (do nothing) or have a second phone for "secure" apps (Banking, Netflix) etc.
- ocdtrekkie 6y agoIf you have wireless chargers and don't really want paid apps, you can reasonably avoid "investing" much in the Apple ecosphere these days: I have not once since switching bought something with a Lightning connector on it, and I rarely use the charger that came with it either. And the new iPhone SE is more or less the cheapest way to get a phone that's updated and well-supported.
- Vespasian 6y agoI might actually take another look at it :)
- josephcsible 6y ago> Enforcing SafetyNet is probably also a net positive change How so? How does SafetyNet make any end-user even slightly more secure?
- blendergeek 6y agoIt does not. Enforcing SafetyNet only makes it harder for users to use custom ROMs. It provides no benefit whatsoever to the end user. It does provide major benefits to app makers who hope to control the user's device.
- Vespasian 6y agoI agree that DRM, and control is probably the main reason why they are doing this. However, most people do not unlock their bootloaders and install custom ROMs. For them having an unlockeded system is an indication of something "bad" happening (spying, fraud, theft) and given how central smartphones are becoming in users life, I prefer that my mothers banking app refuses to work if her smartphones chain of trust is compromised. I also happen to believe that it is impossible to "out-tech" OEMs in the long run and that the path to a fair app ecosystem is through legislation, regulation and anti trust measures. That approach worked in other aspects of the economy and society.
- freedomben 6y agoYou're upset about them requiring hardware attestation in SafetyNet (I am too) so you move to a platform that is way less flexible and way more closed? Not a troll, I'm really curious.
- sitic 6y agoIf my phone has to be a walled garden, Apple's seems more enticing to me for the moment. I would want to give it a try at least. I might very well regret it and switch back to an Android phone which won't get updates after two years. I also have to say that to me, even if apps that require SafetyNet don't work anymore after unlocking, it certainly doesn't make the phone certainly useless. But I don't want to live with the inconvenience of not being able to use some random apps.
- californical 6y agoI can give an anecdote. I love most things about iOS design more than Android, and I've used both, but have stuck with Android over the last 7-8ish years. Mainly because of the amount that I could customize things, freely make little app projects, install custom ROMs, etc. Over the last few years, it's gotten inconvenient to tinker, and I just don't find myself bothering with it anymore. I've run into issues where certain apps stop working because of root. But also both OS's have gotten much better and need fewer (if any) tweaks anyways to be used effectively. Especially with the upcoming change to allow iOS to use a different default browser (finally). If the main reason I've been drawn to Android is vanishing more every year, I'd rather use the more elegant OS (Apple), regardless of how closed it is. I have a Pixel 2 that's getting near EOL (only 2 years after buying it), and I'll be getting an iPhone SE as soon as I can justify spending the money. I guess something that helps too is I've been on a de-googling kick these last few months where I've been switching off all their services because of privacy, another benefit of iOS to me
- homarp 6y agoiOS 14 does not let you use a different default browser engine. It's just the skin that change. It's still Webkit under the hood
- chinhodado 6y ago> apps can't simply access the "external" storage (enforces scoped storage) So how will perfectly valid use cases like file manager or backup manager work now?
- Mindwipe 6y agoA File Manager can ask for root folder access permission but Google will closely control which applications in the Play Store can do so (but if you think that sounds good this is also the same policy they have for SMS access, and Google's enforcement of that has been disastrous as review on the Play Store is a dismal mess). However, this will no longer get you access to Application's own folders, and so backing things up on Android gets even harder and the OS gets more anti-user. (To be clear, this should absolutely be behind a Permission barrier. But to block off user access entirely is a toxic and unhelpful move that makes the platform less useful).
- dredmorbius 6y agoOr the One Android App That Does Not Suck: Termux?
- asveikau 6y agoMedia players are also a big deal for this. I put a lot of audio and sometimes video on my sd card and expect to be able to browse and play it. I am actually doing that right now as I type this.
- Drawde 6y agoSadly it seems that prior restrictions in Android have already taken their toll on Termux: https://news.ycombinator.com/item?id=23224669 https://news.ycombinator.com/item?id=23224669
- dredmorbius 6y agoYeah. So much the worse for Android.
- Noluris 6y agoScoped storage is going to kill all the most useful apps that I use that require full access to storage (such as SyncThing). I'm going to keep using Android 10 until I die. Or just switch to Apple, since if they're going to lock everything down, I might as well go with the company that supports their phones longer than two years.
- kelnos 6y agoMy guess would be that apps that target an earlier Android version will continue to work properly, even on Android 11. Ok, maybe that's more my hope than my guess. We'll see.
- deleted 6y ago[deleted]
- cesarb 6y agoYes, but the other half of that is that Google will require that new uploads to the Google Play Store target newer Android versions. That is, older applications will not break, but newer applications (and newer versions of older applications) will not be allowed to use that loophole anymore. (Of course, you can still sideload...)
- GlitchMr 6y agoAn application can require MANAGE_EXTERNAL_STORAGE permission to access all files.
- Namidairo 6y agoI have a feeling that certain apps will end up forcing their users to accept the popup for this permission in order to continue scanning their storage for "bad" filenames. (A few mobile games rolling their own "protection" by looking for TWRP-related folders, for example)
- GlitchMr 6y ago
- sangfroid_bio 6y agoAnother duopoly that needs more competition is push notification infrastructure. Efficient push notification requires OS vendor server support due to radio usage and agreements with telecommunication companies. Everybody is obsessed with closed app stores and completely missing the net neutrality aspect of the iOS/Android duopoly.
- zozbot234 6y agoIt's not clear that push notifications have to be centralised. The OS could coalesce requests for notifications while still querying multiple sources, thus minimizing the time that radios have to be powered on.
- izacus 6y agoExcept that push notifications also require work on telco's side to make sure they don't accidentally cause large battery use. E.g. there was a long time after Apple introduced push messages where iPhone battery would drain pretty fast because many telcos would have very short connection timeouts on their routing equipment. This forced the phone to wakeup the radio a lot to reestablish connection. This was "fixed" by whitelisting Apple/Google endpoints, so I wonder how that would work in federated environment.
- zozbot234 6y ago> This forced the phone to wakeup the radio a lot to reestablish connection. Perhaps, but if you can tolerate some latency, you might not have to wake the radio all that much. A huge majority of notification use cases can be delivered "late" (at least if the phone is in sleep mode) and still be useful.
- richardwhiuk 6y agoYes, and I believe both GCM and APNS perform cross-app notification coalescing, whereby a low priority notification (e.g. a news article, or some other content update) will picky-back on a high priority notification (incoming call, text message). This is extremely valuable in reducing power usage. (Notifications both exhibit radio usage, but also will typically turn on the display, which is a huge battery sink)
- pantalaimon 6y agoWhat about Magisk? When you have full control over the system, you can pretend everything to Userspace Apps.
- grishka 6y agoIf I understand these SafetyNet changes right, it's now relying on TrustZone, where "trust" frankly means distrusting the end user. This runs on a privilege level above the OS kernel, and it isn't possible to modify that firmware or extract data from it even with the unlocked bootloader, by design. It's currently used for media DRM among other things.
- mschuster91 6y agoJeez, WTF. Looks like I have to buy a new tablet (my old one is on its last legs) before this shit hits the markets, no way I'm gonna have a device that is either not rootable at all or keeps me from using mobile banking. I'm all for more security measures, but not at the cost of giving up my freedom entirely.
- Mindwipe 6y agoThe vast majority of devices sold today already support the hardware, so you're too late if you feel you're not willing to tolerate this.
- dcow 6y agoWouldn't the solution be to allow people who have legitimately unlocked their boot loader to also install a custom attestation root so that safety net can still say “the software running on this phone is the software the user intended and not a malicious 3rd party”? Or maybe safety net is not so much about user safety as it is about platform lockdown and vendor safety. The number of times I’ve been laughed out of a product meeting because I’ve advocated for making decisions that don’t require the apps I’ve worked on to be run on google play services systems... it makes me wonder what is actually important in our industry. It’s certainly not the user privacy, freedom, and advocacy that everyone seems to be milking these days... sad times.
- zozbot234 6y agoBootloader unlock is under user control by definition - it won't happen unless you're physically interacting with the device. The legitimate case for safety net is platform lockdown for things like financial apps. Banks and other financial services like to provide some form of insurance to users wrt. losing money in a security breach, and they can't do this unless the app really is being run on a pristine, locked-down platform. Unfortunately it also impacts sillier things like media streaming and online video games. But the best way to cope with that is simply not to use those.
- kelnos 6y ago> Banks and other financial services like to provide some form of insurance to users wrt. losing money in a security breach, and they can't do this unless the app really is being run on a pristine, locked-down platform. This seems like a weird policy, though. I can access my bank via a web browser on a desktop computer, which is certainly not even remotely a "pristine, locked-down platform".
- realusername 6y agoThat even makes it weirder that a no-name Chinese phone with an unknown ROM is considered more secure than a stock LineageOS just because it's not unlocked...
- Abishek_Muthian 6y ago>I've always trusted CyanogenMod/LineageOS more then than a device manufacturer, but after >10 years of using Android I think it's finally time for me to switch to an iPhone. I'm not trying to go inside Android vs iOS rabbit hole, as it's common knowledge that android's default privacy features pale in comparison to iOS. But in Android you can leverage the trust of an individual app publisher as well and not forced to 'trust the manufacturer'. e.g. Tasker is trusted, it can automate workflows unimaginable in an iOS ecosystem and when Google's API changes broke some of its features; Google listened to the community and whitelisted it. Don't trust default messaging app? Let Signal handle messages. If there's an SMS based exploit, rest assured Signal update to patch that would arrive faster than android update. Got 7 year old android device, which hasn't received any system updates in say (cough) 7 years? But you only use it for web browsing, you can still use latest Firefox for android(with its own engine). Which will support latest PWA API. This can go on and on without rooting android; none of these would be possible in iOS at least not until jailbreak(which compromises security akin to rooting) and probably until Apple steals couple of tricks from the jailbreak community. Finally, If you are talented but poor developer from a village in India/Nigeria/any other place you can develop a PWA web app on a Raspberry Pi and release it for the world to see without any additional charges and probably profit out of it; It would work fine on Android, KaiOS, perhaps upcoming suite of pure Linux smartphone OS, but if you want it to function on iOS you'll have to invest hundreds if not thousands of dollars in equipment, pay yearly $99 fee, develop new native app with probably a new programming language, Give 30% cut to Apple when you make money out of it.
- robin_reala 6y agoTasker looks interesting. Any info on how it compares to iOS Shortcuts? (also, iOS Safari has limited PWA functionality. It’s by no means as comprehensive as Chrome / Firefox on Android, but it was enough for me to make my latest site installable.)
- machello13 6y agoThe last paragraph is a massive exaggeration. iOS doesn't support as many PWA features as some people would like, but it supports plenty. You can't say PWAs simply don't function on iOS.
- throwaway9d0291 6y ago> These are welcome changes in my view, but unfortunately they also seem intend to fix SafetyNet and require hardware attestation that the bootloader is not unlocked [1]. The problem with unlocked devices is that it's a legitimate security risk. With a signed OS and hardware attestation, you can verify with 100% certainty that the foundation of the device's security model is there and fully intact. Upon that foundation you can build features that you might not be comfortable with otherwise, like an OTP app, authenticator app or a payment app. You wouldn't build an "OTP" app for Windows for example because Windows doesn't have a solid security model, it's quite easy for one application to access another application's resources. Once that foundation is broken, all bets are off. If the bootloader is unlocked, you have no way of knowing what's running on a user's device. For all you know, all of the permission checks have been removed and nothing is secure anymore. Even the APIs you'd expect to interact with a secure enclave could be replaced. Others are suggesting that this is the user's choice and so perhaps developers should just deal with it but I disagree. A device isn't necessarily unlocked by the user. A device can be unlocked by anybody with physical access and the passcode. For example a malicious party could install a malicious version of Android on your device if they have unattended access to your phone for a while. They could also buy phones, flash malicious versions of Android and then sell them at a slight loss, making profit off the money stolen from their victims. There's also the problem of malware that gains root privileges. With a locked bootloader, there's limited opportunity for such malware to become persistent. It can't modify the system partition at all. With an unlocked bootloader, it can modify the system partition and permanently modify the OS. Basically, locking the bootloader prevents rootkits. This is why these features are here. They're not here to make enthusiasts' jobs harder, they're here to provide a solid foundation of security upon which an OS that's secure enough to handle high-value information can be built. > When this is enforced for all devices some apps, like the eBay app, won't run on unlocked devices anymore. In some cases (e.g. games), I think this is ridiculous. For apps that deal with finance or other sensitive areas, as explained above, I think this is entirely reasonable. All that said, I can see a world in which we have custom ROMs as well as security: - We make custom signing keys [0] commonplace, not just a thing for Pixel devices. - Set up an automated service through which a device can submit CTS [1] results and have its build of Android whitelisted. [0]: https://android.googlesource.com/platform/external/avb/+/master/README.md#device-specific-notes https://android.googlesource.com/platform/external/avb/+/mas... [1]: https://source.android.com/compatibility/cts https://source.android.com/compatibility/cts
- stiray 6y agoI am running lineage microg rom and I was literally forced to reverse my banking app (for its usage I am paying to my bank) and remove safetynet and various root checks to be able to use it (luckly they are not updating it very often). The android ecosystem is toxic to the point where software developers are raging a war against their users. Luckly there are still projects like lineage and microg where the software is still under control of their users, but google is slowly plugging the holes. I hope that the true linux on phones (pine?) will emerge and stop this exploitation of user rights.
- jhasse 6y ago> I hope that the true linux on phones (pine?) will emerge and stop this exploitation of user rights. Then your banking app won't be available at all.